You signed up for Mediumlink. This policy tells you what data Mediumlink UK Ltd holds about you, what we do with it, and the rights UK GDPR and the Data Protection Act 2018 give you.
1. Who holds your data
Mediumlink UK Ltd is the data controller for your account. Our registered office is in the United Kingdom.
For any privacy question, email [email protected].
2. What we collect
Your account. Email, hashed password, first name, last name, mobile number, Gas Safe registration number, ID card number. At signup you also tell us your company name if you have one, and whether you want marketing messages from us.
Your business. Company name, address, phone, business email, website, logo, signature image.
Your documents. Every certificate, invoice, quote, and job sheet you create. You choose what goes in. That includes your customers, landlords, and tenants. You are the data controller for that customer data. We process it on your behalf.
Your billing. Your Stripe customer ID and subscription status. We never see your card number. Stripe handles every card detail (section 7). We also keep a record of every invoice Stripe issues you: its number, the amount, the dates it covers, and a link to the invoice document. You can read all of it in the app under Settings, Subscription.
Your signup record. When you create an account we store a one-way cryptographic hash of your email address, the date you signed up, whether you took a free trial, and the date you deleted the account if you did. The hash cannot be turned back into your address. This record stays after you delete your account, and it is the only thing that does. It exists so one person cannot delete and re-register to collect the free trial over and over, which would be unfair on everyone paying. Our lawful basis is legitimate interest: preventing abuse of a free offer.
Technical metadata. Your IP address, browser type, session timestamps. Vercel and Supabase log these to keep the app secure and to spot abuse.
Appliance photos. When you tap AI Snap & Fill, you upload a photo of a boiler or appliance nameplate. We send the photo to Anthropic so their AI can read the make, model, and rating. We do not keep the photo unless you save it to a certificate yourself.
3. Why we collect it
| Purpose | Lawful basis |
|---|---|
| Run the app you signed up for | Performance of a contract (UK GDPR Art. 6(1)(b)) |
| Take your subscription payment | Performance of a contract |
| Remind you about upcoming CP12 expiries | Legitimate interest in helping you meet your legal duties |
| Send account and security emails | Legitimate interest in keeping your account safe |
| Send you product news and offers by email or WhatsApp | Consent, only if you ticked the marketing box (UK GDPR Art. 6(1)(a)) |
| Spot abuse and fraud | Legitimate interest in protecting the app |
| Process Snap & Fill photos | Performance of a contract (you triggered it) |
4. Marketing messages
You choose at signup whether we can send you marketing. If you tick the box, we may send product news, tips, and offers about Mediumlink by email or WhatsApp, using the email address and mobile number on your account.
Three promises:
- We only market our own product. We never send you anyone else's adverts.
- We never sell your contact details or share them with marketers.
- You can stop the messages at any moment. Use the unsubscribe link in any email, reply STOP on WhatsApp, or email [email protected]. Stopping marketing never affects your account.
If you left the box unticked, we only contact you about your account, your subscription, and security.
5. Who else sees your data
We use a small set of trusted providers to run the app. Each one sees only the data it needs.
| Provider | What they do | Where |
|---|---|---|
| Supabase Inc. | Database, login, file storage | EU (eu-west-2) |
| Vercel Inc. | Hosting and serverless compute | Global edge, primary US and EU |
| Stripe Payments UK Ltd | Subscription billing | UK and Ireland |
| Resend Inc. | Sending emails | US |
| Anthropic PBC | Snap & Fill image AI | US |
| Cloudflare Inc. | DDoS protection and DNS | Global edge |
We never sell your data. We never let advertisers track you on our site.
6. Data outside the UK
Some of the providers above process data in the United States: Vercel, Resend, Anthropic, Cloudflare. For those transfers we rely on the UK Addendum to the EU Standard Contractual Clauses, and on the UK-US Data Bridge where it applies.
7. Payments
Stripe handles every payment. They hold PCI-DSS Level 1 certification. We never store your card number, expiry, or CVV. Stripe's own privacy policy lives at stripe.com/gb/privacy.
8. AI Snap & Fill
When you photograph an appliance nameplate, we send the image to Anthropic so their Claude vision model can read it. Under Anthropic's commercial terms, your photo does not train their models. Anthropic keeps it briefly in their abuse-detection logs, then deletes it. We never link photos to your customer details.
Only photograph the nameplate. Do not photograph people, children, or any document that holds personal information.
9. How long we keep things
| Data | Retention |
|---|---|
| Your account | While the account is active, then 30 days after you delete it |
| Certificates and invoices | While the account is active. UK record-keeping practice says these should be kept for up to 6 years |
| Stripe billing records and invoices | 6 years (UK tax law requires this) |
| Server logs | 30 days |
| Snap & Fill photos at Anthropic | Up to 30 days, then Anthropic deletes them |
| Signup record (hashed email, signup and trial dates) | Kept indefinitely |
When you delete your account from inside Mediumlink, every item above goes inside 30 days, except items the law tells us to keep for longer and the signup record described in section 2.
The signup record holds no readable email address, no name, and nothing about your work. It is a hash and a handful of dates. Ask us to erase it and we will weigh your request against the reason it exists, as UK GDPR Article 17(1)(c) allows. Email [email protected].
10. Your rights
UK GDPR gives you the right to:
- Ask what data we hold about you
- Ask us to correct anything wrong
- Ask us to delete it (the right to be forgotten)
- Object to processing we run on legitimate-interest grounds
- Restrict processing in certain situations
- Get a portable copy of your data
- Withdraw consent where consent was the basis
- Complain to the Information Commissioner's Office at ico.org.uk
To use any of these, email [email protected]. You can also delete your account yourself inside the app under Settings, User Details, Delete My Account.
11. Security
We use:
- TLS encryption for all traffic
- Salted hashing for passwords
- Row Level Security policies on every table that holds personal data
- Short-lived JWTs for API access
- DDoS protection and a web application firewall through Cloudflare
- Sentry monitoring so we hear about errors fast
No system is perfectly secure. If we detect a breach that affects your data, we tell you and the ICO inside 72 hours where the law requires it.
12. Cookies
Mediumlink sets cookies only to keep you signed in and to remember your interface preferences. We run no advertising cookies. We run no third-party trackers.
13. Children
Mediumlink is for Gas Safe registered engineers. It is not for anyone under 18. We do not knowingly collect data from children.
14. Changes to this policy
For a material change, we email you. You may need to accept the new version before you can keep using the app.
15. How to reach us
Email: [email protected]
Postal: Mediumlink UK Ltd, United Kingdom